SafePay Ransomware VPN Logon Followed by Credential Dumping Within 5 Min
This rule detects potential credential dumping activity against the Local Security Authority Subsystem Service (LSASS) on a host shortly after a successful VPN logon. It correlates Sysmon Event ID 1 (Process Creation) representing known dumping techniques (Mimikatz, Procdump, or comsvcs.dll) with Windows Security Event ID 4624 (Logon) from a VPN source within a 5-minute window.
Splunk (SPL)

